← Back

CVE-2022-22302

nvd nist
Published: Jul 11, 2023Modified: Nov 21, 2024

JSON object

Loading...
3.3
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 1.8 / Impact: 1.4
Source: NVD

Description

A clear text storage of sensitive information (CWE-312) vulnerability in both FortiGate version 6.4.0 through 6.4.1, 6.2.0 through 6.2.9 and 6.0.0 through 6.0.13 and FortiAuthenticator version 5.5.0 and all versions of 6.1 and 6.0 may allow a local unauthorized party to retrieve the Fortinet private keys used to establish secure communication with both Apple Push Notification and Google Cloud Messaging services, via accessing the files on the filesystem.

Affected (7)

2 products
Fortiauthenticator
Fortios
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Fortinet
From 6.0.0 to 6.0.4
Version 5.5.0
Version 6.1.0
Fortinet
From 6.0.0 to 6.0.13
From 6.2.0 to 6.2.9
Version 6.4.0
Version 6.4.1

References (2)

Source: psirt@fortinet.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.